Update SCOPE to the finished USER-WP-0001–0023 surface
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 1s

Replace the WP-0015 planning note with the shipped in/out boundary,
published NetKingdom contracts, operator residuals, and an INTENT
assessment. Fill the repo-boundary neighbor list to match.
This commit is contained in:
tegwick 2026-08-19 14:42:28 +02:00
parent 3a6249b4c6
commit 275bfd530b
2 changed files with 124 additions and 54 deletions

View file

@ -1,8 +1,18 @@
## Repo boundary ## Repo boundary
This repo owns **user-engine** only. It does not own: This repo owns **user-engine** only: user-domain facts, identity-context
mappings, projections, the optional portal, and the adapters that call
neighbors.
<!-- TODO: List what belongs in adjacent repos, e.g.: It does not own:
- SSH key management → railiance-infra/
- State hub code → state-hub/ - OIDC login, tokens, passwords, MFA — key-cape / Keycloak
--> - authorization decisions and protected-system registry — flex-auth
- tenant identifier, grouping, and capability-role authority — tenant-engine
- application-owned first-login profiles and action step-up — consuming apps
- runtime secrets — OpenBao / railiance-platform
- platform audit store — audit-core
- transactional mail — email-connect
- State Hub — state-hub
- published policy site — policy-nexus
- SSH certificates — ops-warden

158
SCOPE.md
View file

@ -2,67 +2,127 @@
## One-Liner ## One-Liner
Headless user-domain and identity-domain integration engine for accounts, Headless user-domain and identity-domain service for accounts, identity
identity links, actor/principal/subject context, preferences, memberships, links, memberships, catalogs, projections, audit, and events, with an
application catalogs, projections, evidence references, audit, and events. optional in-repo portal. It consumes NetKingdom IAM, authorization, tenant
authority, provisioning, and delivery; it does not own them.
## In Scope ## In Scope
- user and account records; - user and account records, and account lifecycle state;
- account lifecycle state; - external identity links keyed by `(issuer, subject)`;
- external identity links; - actor, authenticated-subject, authorization-principal, and user-context
- actor, authenticated subject, authorization principal, account, and user mappings from verified IAM Profile claims;
context mappings; - global, tenant, application, and membership profile values and
- global, tenant, application, and membership profile values; preferences;
- preference values;
- tenant, application, team, and scope memberships; - tenant, application, team, and scope memberships;
- hats, realms, services, assets, access profiles, and active access
context as user-domain facts;
- identity-context read models for domain consumers; - identity-context read models for domain consumers;
- canon interface cards, entity mappings, relationship mappings, and explicit - canon interface cards, entity and relationship mappings, and explicit
gap records; gap records;
- application registry for profile consumers; - application registry for profile consumers;
- customization catalog registry and validation; - customization catalog registry, versioning, and validation;
- effective profile resolution; - effective profile resolution and projections (self-service, admin,
- projection APIs for self-service, admin, application runtime, audit, and application runtime, audit, agent, claims-enrichment);
agent contexts; - local audit records and durable outbox events;
- audit records and lifecycle/profile-change events; - local evidence references derived from audit and events;
- local evidence references derived from audit and event records; - invitations, prepared accounts, entitlement claims, and onboarding
- local standalone development mode; journeys that user-engine owns;
- integration ports for identity claims, authorization checks, events, and - public registration *orchestration* (start, verify, resume, cancel,
runtime secrets; provider handoff) behind an explicit runtime flag;
- adapter contracts for evidence export, policy/control references, and - provider-neutral tenant lifecycle *calls* to the tenant authority
lifecycle task handoff. (create, read, update, retire, reactivate, recover);
- optional CSRF-protected portal over the same APIs (self-service,
onboarding, tenant admin, platform operator);
- standalone/local fixtures and a production PostgreSQL store;
- integration ports for claims, flex-auth decisions (including a rotating
caller token), provisioning, registration verification, tenant
management, outbox delivery, and runtime secrets.
## Out Of Scope ## Out Of Scope
- login and authentication flows; - login, OIDC/SAML token issuance, passwords, passkeys, sessions, and MFA
- password, passkey, session, and MFA lifecycle; lifecycle — `key-cape`, Keycloak, or `local-identity`;
- OIDC/SAML token issuance; - final authorization policy decisions and the protected-system registry —
- final authorization policy decisions; `flex-auth`;
- durable authorization grant authority outside user-engine-owned memberships; - durable authorization grants beyond user-engine-owned memberships;
- policy, control, access-review, exception, and organization source-of-truth - tenant identifier authority, grouping reclassification, and capability
ownership; role grants — `tenant-engine`;
- runtime secret custody; - application-owned first-login profiles, unlink, and action step-up —
- UI implementation in the current MVP; optional registration and access consuming apps (e.g. coulomb-social) and KeyCape client policy;
management UI work is proposed separately under `USER-WP-0014`; - policy, control, access-review, exception, and organization
- full SCIM server or enterprise directory replacement in the initial product. source-of-truth ownership;
- runtime secret custody — OpenBao / Railiance;
- platform audit store and transactional SMTP — `audit-core` and
`email-connect`;
- full SCIM server, enterprise directory replacement, or inbound
SAML/OIDC federation (demand-triggered; Keycloak expanded mode is the
published path);
- a generic extracted profile engine.
The in-repo portal is an optional surface, not a UI product. Password and
MFA screens stay on the identity provider.
## Boundary Rule ## Boundary Rule
user-engine owns user-domain facts, identity-context mappings, and projections. user-engine owns user-domain facts, identity-context mappings, and
Other systems may provide authentication, IAM claims, authorization decisions, projections. Adjacent systems provide authentication, IAM claims,
policy/control authority, deployment, event transport, durable audit, secrets, authorization decisions, tenant authority, policy/control definitions,
organization records, or UI surfaces, but they must integrate through explicit deployment, event transport, durable audit, secrets, organization records,
interfaces rather than becoming hidden sources of profile or identity-domain or additional UI — and they integrate through explicit adapters. They must
truth. not become hidden sources of profile or identity-domain truth.
## Current Planning Governing published contracts:
Implementation and planning work is tracked in `workplans/USER-WP-0001` - IAM Profile v0.3 — https://policy.coulomb.social/standards/iam-profile/v0.3/
through `USER-WP-0015`. `USER-WP-0010` implements the first headless - Tenancy Posture v0.1 — https://policy.coulomb.social/standards/tenancy-posture/v0.1/
registration and factor-evidence slice. `USER-WP-0011` implements prepared - NetKingdom architecture — https://policy.coulomb.social/architecture/net-kingdom/v0.1/
accounts and entitlement claims. `USER-WP-0012` implements hats, realms, - User-engine boundary contract (accepted, not yet published) —
services, assets, access profiles, active context, and exportable `~/net-kingdom/canon/standards/user-engine-boundary-contract_v0.1.md`
access-control facts. `USER-WP-0013` implements onboarding journeys and
welcome protocols. `USER-WP-0014` implements the optional registration and ## Current Status
access-management UI contract facade. `USER-WP-0015` implements registration
scenario and security conformance tests. Workplans `USER-WP-0001` through `USER-WP-0023` are finished. There is no
active workplan. The isolated MVP, multi-tenancy, catalogs, canon
alignment, durable PostgreSQL store, self-service and admin portal,
public-registration orchestration, and flex-auth caller identity (live A2
on `flex-auth-user-engine`) are in the repo and, where applicable, on
Railiance.
Still operator-owned, not remaining product scope:
- public registration and outbox mail stay fail-closed until governed
OpenBao verification/delivery tokens and the transactional SMTP lane
are installed;
- the live tenant-lifecycle probe from a user-engine pod (GET / PATCH /
retire / reactivate on a disposable tenant) is still owed;
- `policy.enabled` and tenant-engine caller `enforce` belong to flex-auth
/ tenant-engine.
## Against INTENT.md
INTENT is the stable aspiration. Against it, the repo now does the job it
set out to do.
| INTENT aim | Status |
| --- | --- |
| Headless user-domain service, provider- and PDP-agnostic | Met. Ports and adapters; production uses IAM Profile v0.3 and flex-auth. |
| Standalone now, multi-tenant / multi-app later | Met. Fixtures and in-memory conformance plus live PostgreSQL and Railiance. |
| Users, links, memberships, catalogs, projections, events | Met. |
| NetKingdom identity-domain integration layer | Met for the owned slice. Consumes KeyCape, flex-auth, tenant-engine, identity-provisioner, audit-core, email-connect. |
| Applications answer who / which scopes / what to project | Met via `/me`, identity context, catalogs, and projections. |
| Not an IdP, PDP, secret store, directory, or org authority | Held. |
| Optional UI, not UI-driven | Held, with a narrower reading: an optional portal now lives *in this repo* over the same APIs. INTENT's "not a UI application" still applies to product identity. |
| Canon-aligned mappings without taking IAM as SoT | Met (`USER-WP-0007`, interface card). Access-review, policy, and control remain references, not owned records. |
| Path from local setup to governed NetKingdom deploy | Met. |
Still aspirational, and deliberately not started here:
- inbound federation / SCIM / directory sync — new workplan only on tenant
demand, targeting published Keycloak expanded mode;
- first-class access-review and governance records;
- a dedicated agent consumption product (projections exist);
- extracting a generic profile engine.
Those remain INTENT, not a hole in SCOPE.